Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1507 MEDIUM 5.5
CVE-2025-59190

Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows Server 2012 HIGH 7.0
CVE-2025-58737

Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

Fix: 10.0.17763.7919 / 10.0.20348.4294+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-58738

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.21161 / 10.0.17763.7919+
Fix from $1,950 2025-10-14
Windows 10 1507 MEDIUM 6.5
CVE-2025-58739

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a networ…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows 10 1507 MEDIUM 6.5
CVE-2025-59185

External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows Server 2016 MEDIUM 5.5
CVE-2025-59184

Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose informatio…

Fix: 10.0.17763.7919 / 10.0.20348.4294+
Fix from $1,600 2025-10-14
Windows 11 22h2 HIGH 7.0
CVE-2025-58731

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.20348.4294 / 10.0.22621.6060+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-58732

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-58733

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-58734

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-58735

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-58736

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.8
CVE-2025-58728

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.5
CVE-2025-58726

Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 21h2 HIGH 7.0
CVE-2025-58727

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an a…

Fix: 10.0.19044.6456 / 10.0.19045.6456+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-58730

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 MEDIUM 6.5
CVE-2025-58729

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Remote Desktop Client HIGH 8.8
CVE-2025-58718

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 1.2.6599 / 2.0.706.0+
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.8
CVE-2025-58720

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information …

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,950 2025-10-14
Windows 10 1607 HIGH 7.8
CVE-2025-58722

Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8519 / 10.0.17763.7919+
Fix from $1,950 2025-10-14
Azure Connected Machine Agent HIGH 7.8
CVE-2025-58724

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.57+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-58725

Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 8.8
CVE-2025-58715

Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 8.8
CVE-2025-58716

Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-55701

Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-58714

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows Server 2022 23h2 HIGH 7.8
CVE-2025-55697

Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.

Fix: 10.0.25398.1913 / 10.0.26100.6899+
Fix from $1,950 2025-10-14
Windows 11 24h2 HIGH 7.7
CVE-2025-55698

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.

Fix: 10.0.26100.6899 / 10.0.26200.6899+
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.0
CVE-2025-55696

Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges …

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,950 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-55699

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14